Threat Level: green Handler on Duty: Russ McRee

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Content-Length
Strict-Transport-Security
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
ETag
Accept-Ranges
Expect-CT
X-XSS-Protection
Pragma
X-Powered-By
CF-RAY
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Access-Control-Allow-Origin
Referrer-Policy
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
P3P
X-UA-Compatible
X-Served-By
X-Xss-Protection
X-Download-Options
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
CF-Ray
X-Adblock-Key
X-Request-ID
Access-Control-Allow-Credentials
X-FRAME-OPTIONS
X-Request-Id
X-Permitted-Cross-Domain-Policies
X-AspNet-Version
Alt-Svc
Content-Security-Policy-Report-Only
X-Runtime
X-DNS-Prefetch-Control
X-Drupal-Cache
X-Check
X-Cache-Status
X-Generator
X-Cacheable
Timing-Allow-Origin
X-Iinfo
X-Envoy-Upstream-Service-Time
X-Content-Security-Policy
X-Drupal-Dynamic-Cache
Feature-Policy
Content-Encoding
Access-Control-Expose-Headers
Upgrade
Status
X-CDN
X-AspNetMvc-Version
P3p
Access-Control-Max-Age
X-Via
Server-Timing
X-UA-Device
X-Robots-Tag
Request-Context
X-Turbo-Charged-By
X-Cache-Group
X-Amz-Request-Id
EagleId
X-Amz-Id-2
X-Backend
X-AH-Environment
Keep-Alive
X-Proxy-Cache
X-Server
X-Ws-Request-Id
X-Age
X-Ua-Compatible
Host-Header
X-Hacker
Cf-Edge-Cache
X-Vhost
X-Server-Powered-By
X-Rq
X-Varnish-Cache
Allow
X-Dispatcher
X-Amz-Version-Id
Grace
X-Swift-SaveTime
X-Swift-CacheTime
Ali-Swift-Global-Savetime
X-OneAgent-JS-Injection
X-LiteSpeed-Cache
X-Dns-Prefetch-Control
X-WebKit-CSP
Accept-CH
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Page-Speed
Cf-Apo-Via
X-Device
Cf-Railgun
X-Aws-Lambda-Call-Status
X-Server-Id
X-Host
X-Node
X-Pingback
X-Cache-Spec
X-Nginx-Cache-Status
X-Akam-SW-Version
Surrogate-Control
EagleEye-TraceId
X-Backend-Server
Request-Id
X-Ruxit-JS-Agent
X-Readtime
X-Cache-Lookup
X-HW
X-Cloud-Trace-Context
X-Content-Security-Policy-Report-Only
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
Accept-CH-Lifetime
X-Trace
X-Application-Context
X-Response-Time
Permissions-Policy
X-Nginx-Upstream-Cache-Status
Fastly-Restarts
X-Mod-Pagespeed
X-Edge
X-WebKit-CSP-Report-Only
X-CST
Content-Location
Accept-Ch-Lifetime
X-Content-Type
X-Mcache
X-MS-InvokeApp
X-Url
X-Country
X-Clacks-Overhead
Rating
X-Midtier
X-TtlSet
X-Amz-Server-Side-Encryption
X-Vname
X-PC
X-ECACHE
X-Litespeed-Cache
RTSS
X-VARITI-CCR
Cache-Tag
X-Vcap-Request-Id
X-Element-Page-Cache
X-D2id
Verso
Origin-Trial
X-Use-Magma
X-Kinja-Server
X-Cdn-Fetch
X-Exp-Variant
X-Exp-Id
X-GoogleNews-Bot
X-Kinja
X-Kinja-Revision
X-Kinja-Build
X-Ac
X-ESI
X-Varnish-TTL
X-Rack-Cache
X-Server-Name
X-Cnection
Service-Worker-Allowed
X-Powered-By-Plesk
X-Ttl
X-B3-TraceId
X-GitHub-Request-Id
X-Cache-TTL
Xkey
SPRequestGuid
X-SharePointHealthScore
X-Navigation-Version
X-Abt-Application-Version
X-Amz-Rid
X-NWS-LOG-UUID
X-Client-IP
Edge-Control
X-Cached
SPRequestDuration
SPIisLatency
Arr-Disable-Session-Affinity
X-Mg-S
X-Server-Lifecycle-Phase
X-Kraken-Loop-Name
X-Instrumentation
X-Erf-Bev-Bev-Is-Generated
X-Upstream
X-Erf-Bev-Bev
X-Browser-Type
X-Px
X-Cache-Key
X-Dw-Request-Base-Id
X-Correlation-Id
X-Sol
X-Middleton-Display
Display
Pagespeed
Content-MD5
X-SRCache-Fetch-Status
X-SRCache-Store-Status
Access-Control-Request-Method
X-NF-Request-ID
Edge-Cache-Tag
X-Goog-Hash
X-Fastcgi-Cache
X-XRDS-Location
X-Country-Code
Front-End-Https
X-Version
X-Daa-Tunnel
X-Forwarded-For
X-Id
Public-Key-Pins
X-Powered-CMS
TCN
AR-SID
AR-PoweredBy
AR-ATIME
AR-CACHE
AR-Request-ID
X-Recruiting
X-MSEdge-Ref
X-T
X-Content-Digest
X-HP-Trace-Id
X-Jurisdiction
X-HP-Webp
X-Accel-Expires
Response
X-Middleton-Response
X-RateLimit-Remaining
X-Ser
TP-Cache
TP-L2-Cache
X-Shield-Request-Id
X-Amzn-Trace-Id
MRF-Tech
Mrf-Cache-Status
X-B3-TraceId-Primal
Nginx-Cache
S
X-Ratelimit-Limit
X-Request-Processing-Time
X-Request-Received
X-Webkit-Csp
Server-Node
X-HS-Hub-Id
X-HS-Combine-CSS
MicrosoftSharePointTeamServices
X-HS-Cache-Config
X-HS-Content-Id
X-Distributor
Cache-Status
X-Hits
X-Edge-Location-Klb
X-Kinsta-Cache
Cache-Tags
X-Ratelimit-Remaining
Fastcgi-Cache
X-Fastly-Request-ID
X-Grace
X-FastCGI-Cache
Alternate-Protocol
Server-Name
X-DataDome
X-Origin-Server
X-LB-Cache
X-Ezoic-Cdn
X-DIS-Request-ID
X-Ua-Browser
X-Ratelimit-Reset
X-Geo-Country
X-Protected-By
X-Request-Handler-Origin-Region
X-Microsite
X-TEC-API-VERSION
X-TEC-API-ORIGIN
X-TEC-API-ROOT
X-Rid
Cross-Origin-Opener-Policy
X-Frontend
Filterid
X-Debug-Info
X-Logged-In
X-Varnish-Backend
X-Git-Hash
X-Www-Served-By
Healthy
X-FB-Debug
Cleartype
Payment
X-Page-Id
X-Forwarded-Proto
X-NGENIX-Cache
X-Load-Cache
X-LLID
X-Hostname
Charset
X-Cluster-Name
Content-Disposition
X-B3-Sampled
X-Origin-Cache
DC
X-ASPNET-VERSION
MS-Author-Via
X-GUploader-UploadID
X-Goog-Metageneration
X-VCache
X-PressLabs-Stats
X-Kong-Proxy-Latency
X-Kong-Upstream-Latency
X-TTL
X-Upgrade-Enabled
Access-Control-Allow-Method
X-Ruxit-Js-Agent
X-Proxy
Realpath
Accept-Ch
X-F-Cache
Retry-After
X-ORACLE-DMS-ECID
X-ORACLE-DMS-RID
Accept-Charset
X-Az
X-AppVersion
X-Activity-Id
Cross-Origin-Resource-Policy
X-Seen-By
Paypal-Debug-Id
X-Contextid
X-Signature
X-Type
X-Oracle-Dms-Rid
X-Oracle-Dms-Ecid
X-Amz-Meta-S3cmd-Attrs
X-Amz-Replication-Status
X-B-Cache
X-Revision
X-Route-Name
X-Whom
X-Request-Guid
Viewport
X-Is-Crawler
X-Azure-Ref
X-Fb-Rlafr
X-Flags
X-Hosted-By
X-Providence-Cookie
X-Aspnet-Duration-Ms
Surrogate-Key
X-Wix-Request-Id
X-Varnish-Server
X-DynaTrace
X-TT
X-B
Amp-Access-Control-Allow-Source-Origin
X-App-Environment
Count-Hit
X-B3-Traceid
X-Aspnetmvc-Version
X-Akamai-Edgescape
X-Language
X-Source
Referer-Policy
X-App-Server
X-Goog-Stored-Content-Length
X-Goog-Stored-Content-Encoding
X-Mobile
X-Goog-Storage-Class
X-Goog-Generation
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Template
X-Cache-Control
Host
X-Magnolia-Registration
X-COUNTRY
X-RateLimit-Limit
X-Varnish-Grace
Version
X-N
X-EdgeConnect-Cache-Status
X-HTML-Minification-Powered-By
X-Cache-Rule
SRV
X-Original-Request-Id
X-Tumblr-Pixel
X-Tumblr-User
X-Tumblr-Pixel-1
X-Tumblr-Pixel-0
X-Response-Served-From
X-Varnish-Age
X-UUID
X-Rule
VIX-Pulpo-Upstream-Status
Section-Io-Cache
Access-Control-Request-Headers
VIX-Pulpo-Node
X-Cache-Time
X-Cache-Status-Check
SD-X-WS
X-Envoy-Decorator-Operation
X-RTag
Ms-Operation-Id
MS-CV
X-Framework
X-Content-Powered-By
X-FW-Static
X-FW-Version
X-Device-Type
X-FW-Type
X-FW-Server
X-Cacheable-TTL
X-Backend-Name
X-ProcessESI
X-Page-View
X-FW-Dynamic
X-RemovedCookies
Refresh
Protected
X-FW-Serve
X-FW-Hash
X-Cache-Expired-At
X-Cache-Grace
X-Adobe-Content
X-Adobe-Loc
Akamai-GRN
X-Environment-Context
GEO-INFO
NGB
X-Http-Reason
X-L-Path
X-Is-Bot
X-NYM-Debug-Backend
X-Servername
X-User-Agent
X-Status
X-Instance
X-Rendered-As
X-G
Url
X-Jobs
X-Trace-Id
X-Akamai-Request-ID2
X-CDN-Forward
X-Drupal-Cache-Contexts
CDN-RequestId
X-Drupal-Cache-Tags
X-Debug-IsConnected
X-Debug-IsPreview
WPO-Cache-Status
WPO-Cache-Message
X-Cache-Age
From-Origin
X-Region
X-Yottaa-Optimizations
Front
X-Cache-Hit
X-Fastly-Request-Id
X-Yottaa-Metrics
Accept-Language
X-Times
X-Amzn-RequestId
Country
X-Amz-Apigw-Id
X-Tb
X-Newrelic-App-Data
X-Nginx-Cache
X-Tt-Logid
Backend
Pinterest-Version
X-Pinterest-Rid
X-Node-Name
Pinterest-Generated-By
X-Content-Options
X-ECache
Fastly-SWR
Fastly-SIE
X-Zen-Fury
X-Unique-Id
X-Real-IP
X-DynaTrace-JS-Agent
X-VC-Cache
X-Mode
Content-Secure-Policy
Uber-Trace-Id
X-Cache-Operation
X-TIME
X-Air-Hostname
Fastly-Drupal-HTML
X-Air-Source
X-Air-Trace-Id
X-Tec-Api-Version
X-Tec-Api-Origin
X-Tec-Api-Root
Meta-Geo
X-Buckets
Webserver
X-Rewrite-Enabled
X-Tumblr-Pixel-2
X-RN-RSRV
Filters
X-UPSTREAM-Address
X-Generation-Time
X-Web-Node
X-Rocket-Nginx-Serving-Static
X-Content-Age
X-Section
Azure-InstanceId
Azure-Version
Onion-Location
Azure-SlotName
CF-IPCountry
Azure-SiteName
X-Amzn-Remapped-Content-Length
X-Format
X-Cache-Server
Azure-RegionName
X-Proxy-Cache-Info
X-Access
X-Locale
X-IPLB-Request-ID
X-Proto
X-Proxy-Cache-Status
X-ProxyCache-Key
X-IPLB-Instance
X-Debug
X-Adobe-Source
X-BYPASS-REASON
X-Cache-TTL-Remaining
X-Cms-Context
X-ProxyCache-Status
X-R9-Blue-Green-Version
X-Sucuri-Cache
X-Sucuri-ID
X-Ua
X-Via-Fastly
X-Sql-Duration-Ms
X-Sql-Count
X-Reqid
X-Say-Cacheable
X-SayCDN-TTL
X-Soup
Cache-Hits
X-Say-TTL
X-IPS-LoggedIn
X-SRV
Property-Id
Webcakes-Region
Webcakes-App-Version
X-Server-W
X-Skip-Cache
Web-Mar-Node
X-Cluster
X-PHP-Host
X-Origin-Hint
X-Site-Version
S-Rt
TWC-GeoIP-Country
TWC-Device-Class
TWC-GeoIP-LatLong
TWC-Locale-Group
TWC-Privacy
TWC-Connection-Speed
X-Cache-Host
Webcakes-App-Name
X-LJ-Flow-ID
ServerID
X-PHP-Backend
X-Ms-Version
X-No-Session
X-Cache-Action
X-Handled-By
X-Forwarded-Host
X-VWS-Id
ServedBy
X-Labrador-Cache-Channel
Liferay-Portal
Node
X-AWS-Id
X-Varnish-Beresp-Grace
Apigw-Requestid
X-Ms-Request-Id
X-UA-Device-Type
Cache-Name
X-GeoCountry
X-Proxied
Cross-Origin-Window-Policy
X-LSADC-Cache
X-LAGOON
X-Edge-Location
X-Extlb
X-Zipkin-Id
X-Xfnlog-Site
X-JoinUs
X-GeoCode
X-Routing-Service
X-Urbn-Context-Path
X-SaId
X-Urbn-Site-Id
Locale
X-Detected-As
X-Time
WP-Super-Cache
X-WP-CF-Super-Cache
X-WP-CF-Super-Cache-Cache-Control
X-CACHE-AGE
X-Cluster-Node
X-Timing-Wait
Selected-Fe
Mn-Server-Ip
Mime-Version
X-Proxy-Build
X-URL
CDN-PullZone
CDN-EdgeStorageId
CDN-CachedAt
CDN-Cache
CDN-Uid
CDN-RequestCountryCode
DB-Nickname
Fastcgi-Useragent
X-FB-TRIP-ID
X-Optimistic-Header
X-Hl-Ver
X-Server-ID
X-Origin-Date
X-Tumblr-Pixel-3
Source
X-XRDS-LOCATION
CF-Cached-On
X-Uri
X-Redis-Cache
X-Oneagent-Js-Injection
X-Request-Time
X-Cache-Debug
X-GEO
X-Generated-By
X-Director
X-Varnish-Hits
X-Loop
X-Mg-Request-UUID
X-TNCMS
X-Presslabs-Stats
X-ARC
Countrycode
Upgrade-Insecure-Requests
X-App-Version
X-Tx-Id
Xserver
X-Akamai-Transformed
Xet-Cookie
X-Pass-Why
X-Origin-TTL
X-Origin-CC
Frame-Options
X-FireWall-Port
X-NWS-UUID-VERIFY
X-Varnish-Beresp-Ttl
Cache-Tv-Group
X-Varnish-Cache-Hits
X-Storefront-Renderer-Rendered
X-Varnish-Hostname
X-Storage
X-Sorting-Hat-ShopId
X-ShardId
X-ShopId
X-Shopify-Stage
X-Sorting-Hat-PodId
X-Alternate-Cache-Key
X-Service
X-Varnish-Ttl
X-Newrelic-Synthetics
X-ServerID
X-Datadog-Parent-Id
X-TA-CDN-Provider
X-Datadog-Sampled
X-Datadog-Trace-Id
X-RM-Cache-TTL
X-Tid
X-Datadog-Sampling-Priority
X-DC
X-Endurance-Cache-Level
Environment
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
X-Ec-Fail
MD5-Digest
X-Developer
X-A
WWW-Authenticate
X-Destination
X-We-Are-Hiring
X-Gdpr
X-Generated-On
Candidate-Md5Url
X-Frame-Option
Gannett-Cam-Experience-Id
X-BCube-Filmed-By
X-VG-TLSProxy
X-A-Ccd
X-A-Dam
X-Aed
X-Core-Value
X-A-Wwc
X-Vdms-Version
X-Bc-Bl
X-Conf
Lang
A
X-CMSURLCustom
X-Vdms-Path
X-Rojux
BehaviorPad-Version
Host-ID
X-Request-Host
X-D
X-S-Cookie
X-A-Dgt
X-S
X-A-Dcw
X-Cache-NE
X-Cache-Info
Req-Svc-Chain
X-Platform-Cluster
Rendered-Blocks
X-Platform-Processor
X-Thinkindot-L3
X-TIM-N
X-B-Cookie
X-Origin-Time
X-B3-Spanid
X-ScT
X-Platform-Router
Odigeo-Trace-Id
Ngx.Var.Host
X-Served-From
Meta-Geo-Continent
Origin
Redirect-Candidate
X-Processor
Release
Edge-Cache
DCR-Processing-Time-Ms
Xc-Version
Thinkindot-CacheControl
X-S-Maxage
TDXMobile
X-Application
X-INCAP-ABP
X-BBC-Edge-Cache-Status
Thinkindot-Control
Thinkindot-CacheControl-Type
X-Level-Front-Cache
X-Loc
X-Nyt-Route
Sslversion
DCR-Decision-By
X-Mobile-URL
X-Mid
X-SRCache-Key
T-Server
Surrogated-Key
X-Pubstack
X-Auto-Login
Tube-Get-Contents
Server-Host
Memcached
Magicmarker
State
Tube-Got-Eval
Vix-Hermes-Req-Id
Tube-Got-Results
X-Akamai-Device-Characteristics
X-Req
X-Varnish-Beresp-Status
X-Origin-Response-Time
X-SB
X-WADP-Cache
X-Old-Content-Length
X-WA-Info
X-JWT-State
X-Varnish-CookieHashed-On
X-Location
X-NodeID
X-Thanos
X-Test
X-WP-CF-Super-Cache-Active
X-Sn-Servicetimems
X-Sigma-Backend
X-Platform-Server
X-Sigma
X-Varnish-CookieINHashed-On
X-SD-PageType
X-SVT-ORM-VERSION
X-SVT-ORM-RULES
X-Pool
X-Is-Gdpr
X-Human
X-Rocket-Build-Number
X-Varnish-Remaining-TTL
X-CUA
X-DefElseHash
X-Core-Mission
X-Clara-WADP
X-Cache-Bucket
X-Cdn-Origin
X-Restarts
X-Cdn-Srv
X-Worker
X-DefHash
X-GeoIP-City
X-Has-Esi
X-HS-Content-Campaign-Id
X-Httpd
X-Geo-Header
X-Fmm-Version
X-Developers
X-Ec-Custom-Error
X-VServer
X-Bip
Tube-Return
CloudFront-Viewer-Country
Cluster
Apple-News-Services-Host
Click-Count-Error
Click-Count-Action-Start
Fastly-GeoIP-CountryCode
Apple-News-Services-Parsed-Url
Country-Code
CacheControlHeader
Decoy-Debug-Key
AKAMAI
Apple-News-Services-Handled
Decoy-Debug-Status
DSUID
Decoy-Debug-TTL
Apple-News-Services-Request-Url
Fastly-Backend-Name
C-Via
Gh-Request-Id
Cache-Host
Server-Info
Section-Io-Id
Section-Origin-Responded
SID
Section-Io-Origin-Status
X-Parent-Response-Time
Section-Io-Origin-Time-Seconds
Web-Mar-Region
We-Hiring
X-LB-NoCache
X-Ad-Defer-Variation
X-Accel-Expires-Debug
Cache-Key
X-Irp-Debug
X-Men
X-Minions-Version
X-Mvc-Supplant-Cachable
X-Accel-Buffering
Cache-Provider
X-Azure-Ref-OriginShield
X-Fastly-Backend
X-FC-Vary-Parameters
X-Fetched-On
X-Cache-Id
X-Cache-Tags
X-CacheTTL
X-Dispatcher-Number
X-Dispatcher-Server
X-DPWN-IS-SECURE
X-Esi-Check
X-Gamma-Serve
X-Gen-Mode
X-Gzip
X-Hash
Adler-Geo
X-App
X-GeoIP-Region-Code
X-GeoIP-Country-Code
X-Cache-Backend
X-Block-Status
X-GeoIP
X-Hnp-Log
X-Op-Id-All
Origin-CC
On-Server
NM-Fastcgi-Cache
X-Slack-Backend
Origin-EX
X-Scale
Producers
X-NCache
Pics-Label
X-Slack-Shared-Secret-Outcome
X-Var-Ttl
X-Wix-Viewer-Type
NGX
Is-Eu
X-Cache-Date
L
X-Vmg-Version
X-Variation
Mail-Subject
Machine
X-Request-Start
Platform
CDCHOST
X-Node-Id
Cmstype
Cmsid
X-Date
X-Origin
X-Org
X-Nginx-Cache-Key
Ssr
Server-Ext
X-Region-Sid
Server-Hostname
User-Cache-Control
X-Platform
Sever-Int
X-Qloud-Router
X-Device-Os
X-Varnishpool
X-VarnishDD-TTL
X-Up
X-Forwarded-Site
X-Server-IP
X-Refresh
HA-Ipaddr
X-HN
X-Owner
X-Planisys-CDN-Cache
X-Planisys-CDN-Rules
X-Eu-Site
X-Planisys-CDN-TTL
Wxu-Next-Hostname
X-CGP
X-Ckpd-Fst-Backend
Canary
Fastly-SSL
Wxu-Next-Commit
Ha-Gx-Prefs
PFcat
Wxu-Next-Region
X-Csrf-Jwt
Datacenter
Kp-EeAlive
L5d-Success-Class
X-Cache-FS-Status
X-Microcachable
X-Mly-Id
Load-Balancing
X-Mvc-Supplant-OutputCached
X-Nananana
Svr
X-Cache-Remote
X-Esi
X-V-Cache
X-Webkit-CSP-Report-Only
X-AIR-PT
Env
GeoIP-Latitude
X-Tb-Optimization-Total-Bytes-Saved
X-Aicache-OS
X-Servedbyhost
X-CSRF-Token
X-Client-Ip
X-Api-Version
X-Via-Popn
X-Via-Poph
X-Via-Popv
HostName
X-Origin-Expires
X-Instance-Name
X-Cached-By
X-Nc
X-RCS-CacheZone
X-Zone
X-Fastly-Cache
X-ND-Cache
X-HA-Backend
X-Trace-ID
X-NGINX-Cache
Cdn
X-Wa
X-Response-By
Server-ID
X-DataCenter
X-VC
Cache
X-NewRelic-App-Data
Time
Expect-Staple
Cdnsip
X-Release
Memory
X-FL-EDGE
Srvid
X-AK-Request-ID
X-HS-Status
Locid
X-FL-QIT-DEBUG
Cdncip
X-Generated-In
X-Vc
X-ZONE
X-Webkit-CSP
X-Via-CDN
X-Provided-By
X-Cache-Enabled
X-From
X-Fpc
X-Gateway-Skip-Cache
X-Gateway-Request-Id
X-Air-Pt
X-Gateway-Cache-Status
X-Gateway-Cache-Key
NtCoent-Length
Edge-Copy-Time
X-Via-Edge
X-Via-SSL
X-CS
X-LB-ID
Hostname
X-Edge-Pop
X-Via-NSCOPI
X-Check-Cacheable
X-API-Version
X-Correlation-ID
X-Vgn-Hpd-Variations-Key
GeoIp-Country-Code
X-Vgn-Hpd-Ssi
X-Vgn-Hpd-Cached
X-CCDN-CacheTTL
X-Vcl-Version
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-CSRF-TOKEN
X-Lambda-Id
Eomportal-Instance
X-Debug-Cache-Store
X-Debug-Cache-Fetch
X-Dc
X-Via-JSL
X-APP-VERSION
X-Micro-Cache
AMP-Access-Control-Allow-Source-Origin
Ngx-Var-Key
True-Client-IP
X-Proxy-CacheRZ
XkeyRZ
Sid
VNS-Cache
X-MCACHE
CPC-Age
CPC-Cache
VNS-Age
X-Amz-Meta-Cb-Modifiedtime
X-Vtex-Remote-Cache
X-B3-SpanId
X-Srv
OT-Force-Account-Verify
X-Request-URI
Path
X-Nf-Request-Id
X-Render-Time
X-SIPLIST1
IsBot
X-Cache-NGX
X-Fastly-Country-Code
X-VCL-Version
Uri
X-Info
X-Cs
X-EC-Lua
X-TH-Server
X-ATG-Version
True-Client-Ip
X-VCT
Srv
X-MSEdge-Flight
X-Varnish-Authentication
X-MSEdge-Features
X-Contensis-Viewer-Groups
X-Cache-ASPX
Fastly-Drupal-Html
Location
X-Upstream-Ht
X-Upstream-Ct
Request-ID
X-Cache-Type
X-SERVER-NAME
Resin-Trace
M-TraceId
Esi-Enabled
X-CF-Lambda-Version
X-PAYTM-SRV-ID
X-Oss-Storage-Class
X-Cache-Expires
X-CF-Lambda-Fn
X-Oss-Server-Time
X-Oss-Request-Id
X-Udemy-Cache-App-Namespace
GeoIP-Country-Code
X-Oss-Hash-Crc64ecma
X-Cdn-Request-ID
CDN
X-Edge-POP
X-CLOUD-TRACE-CONTEXT
X-RateLimit-Remaining-Second
X-RateLimit-Limit-Second
X-Oss-Object-Type
X-Lb-Id
X-Accel-Version
Servername
X-FPC
Cross-Origin-Opener-Policy-Report-Only
X-Varnish-Beresp-TTL
X-Akamai-Pragma-Client-IP
XServer
X-TX-ID
YJS-ID
X-Wikidot-Static-Cache
LB
X-Wikidot-Backend
X-Pod-Name
RNT-Time
RNT-Machine
Sm-Log-Id
X-Service-Response-Time
Traceparent
X-Datacenter
Timeexpire
X-Moov-Xdn-Version
X-Moov-T
X-Shop-Environment
N-Cache
X-CDN-Cache-Status
X-RateLimit-Reset
X-Forwarded-Path
X-Bl-Debug
X-Datadome
X-Orig-Expires
HIT
X-Scheme
CountryCode
X-Tenant
X-MP-GENERATED-AT
X-B3-Trace-ID
X-Cdn-Cache-Status
X-ApacheServer
X-Viewer-Country
X-PERF
X-WA
Server-Id
X-Geo
X-Policy
X-App-Name
Ohc-File-Size
X-CACHE-KEY
X-NC
X-Srcache-Fetch-Status
X-Ha-Backend
X-Srcache-Store-Status
Proxy-Connection
FSS-Cache
X-FORWARDED-FOR
X-Rebelmouse-Surrogate-Control
X-Rebelmouse-Cache-Control
X-Via-PopN
X-Snapshot-Date
X-Via-PopH
X-NAPM-TraceId
Epwk-X-Cache
X-LiteSpeed-Cache-Control
X-ServedByHost
Powered-By
X-Via-PopV
ENV
X-TraceId
X-MiniProfiler-Ids
Yjs-Id
X-Dw-Trace-Id
X-Cdn-Forward
X-Amz-Meta-Opti
WZWS-RAY
X-Hyper-Cache
Geoip-Latitude
Cneonction
X-M-Log
X-M-Reqid
Rip
X-TRACE-ID
User-Agent
Ngx
Content-Style-Type
Content-Script-Type
V-Age
True-Client-Country-4JS
X-Qnm-Cache
Ec-Rule-Version
X-RAMCache
X-Lb-Nocache
X-B3-Parentspanid
Hit
X-Serial
X-Fastly-Backend-Reqs
X-Swift-Error
X-Acquia-Site
Inserted-Into-Cache-At
Tracecode
X-Clientip
X-Vgn-Hpd-Reason
X-Acquia-Application-Trace
X-Acquia-Purge-Tags
X-Acquia-Application-UUID
X-Wp-Cf-Super-Cache
X-F-Status
X-Wp-Cf-Super-Cache-Cache-Control
X-TT-LOGID
X-Lsadc-Cache
Req-ID
X-Fastly-Cache-Hits
X-Webstats-RespID
Lb
X-Th-Server
X-UP
MIME-Version
X-Cache-Ngx
Warning
X-B3-ParentSpanId
X-IPS-Cached-Response
My-App
X-LiteSpeed-Tag
X-Stale
XM
X-Mid-Debug-Cache-Disk
X-Mid-Debug-Cache-Key
X-Request-URL
X-VG-WebCache